CVE-2026-14895Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex engine retries the match at each offset of a long whitespace run, producing quadratic backtracking. The fix replaces \s*$ with \s+$. Any caller that passes untrusted input to trim or rtrim can trigger CPU exhaustion with a string containing a long run of whitespace.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-08)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-07: 1Mentions · 2026-07-08: 2Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 207-0707-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-071
Disclosure1
2026-07-082
Disclosure2
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-14895: String::Util before 1.36 are susceptible to a regular expression DoS https://www.openwall.com/lists/oss-security/2026/07/07/18

    Post summary

    The CVE-2026-14895 is a newly disclosed regular expression DoS vulnerability in Perl CPAN's String::Util before version 1.36, with no known exploits, patches, or active exploitation noted.

    10010185
    4.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14895 String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing whitespace with … https://www.cve.org/CVERecord?id=CVE-2026-14895 ----- Traducción: CVE-2026-14895 Str… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑14895, describing a regex denial‑of‑service vulnerability in Perl’s String::Util (pre‑1.36) and provides links to the official CVE record.

    0000036
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14895 String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing whitespace with … https://www.cve.org/CVERecord?id=CVE-2026-14895

    Post summary

    The text announces CVE-2026-14895, describing a regex‑based denial of service in String::Util versions prior to 1.36 for Perl, with no details on PoC, exploits, or patches.

    00000727
    57.7K followersView on X

Explore more